What the vulnerability does
01Description
WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields. Attackers can insert JavaScript payloads in the dady_input_text or dady2_input_text fields via the plugin options panel to execute arbitrary code when the page is viewed.
Explanation of Vulnerability in Simple Terms
02Summary
A cross-site scripting (XSS) vulnerability in 3dady Real-Time Web Stats allows an attacker to inject malicious scripts that execute in other users' browsers. The vulnerability requires low-level authentication and user interaction, such as clicking a malicious link. The impact is limited to the scope of the vulnerable component.
What an attacker can do
03Attacker Capabilities
Inject and execute malicious JavaScript in other users' browsers when they interact with the affected component.
Potential impact on your site
04Site Impact
Users viewing the affected component may have their sessions compromised or be redirected to malicious sites.
Conditions required to exploit
05Prerequisites
Attacker must have low-level authentication and the victim must click a malicious link or visit a crafted page.
Key dates
06Disclosure timeline
May 10, 2026
CVE published
May 26, 2026
Record updated